To set up access control in Nginx Proxy Manager, open the admin UI, go to Access Lists, and click Add Access List. Give the list a name, add a username and password on the Authorization tab and/or allow and deny rules on the Access tab, and save it. Then edit a proxy host, choose your new list in the Access List dropdown on the Details tab, and save. Nginx Proxy Manager then blocks anyone who doesn’t match the list’s rules or can’t sign in.
This guide walks through every setting in the Access List dialog, shows how the IP rules and password prompt work together, and covers testing, common mistakes, and fixes when you get locked out or everyone gets let in. Menu names below match recent versions of Nginx Proxy Manager; newer releases with a redesigned interface may place things slightly differently, but the options are the same.
What an access list does
An access list is a reusable set of rules you can attach to one or more proxy hosts. It can protect a site in two ways:
- HTTP basic authentication – visitors see a browser sign-in prompt and must enter a username and password you define.
- IP allow and deny rules – requests are allowed or refused based on the visitor’s IP address or network range, written in CIDR notation (for example, 192.168.1.0/24).
Behind the scenes, Nginx Proxy Manager turns these settings into standard Nginx auth_basic, allow, deny, and satisfy directives for each host that uses the list. That means you get Nginx’s well-tested access control without editing config files.
Before you start
- You need admin access to the Nginx Proxy Manager web UI (usually on port 81).
- Know the IP ranges you want to allow, such as your home LAN (often 192.168.1.0/24 or 192.168.0.0/24) or a VPN subnet.
- Keep another way into the admin UI (for example, directly by its local IP and port 81). Access lists apply to proxy hosts, not the admin port itself, but a mistake on the host you use to reach the admin panel can lock you out of that route.
Step 1: Create a new access list
- Sign in to the Nginx Proxy Manager admin UI.
- Click Access Lists in the top menu (in some versions it’s under Hosts or in the sidebar).
- Click Add Access List. A dialog opens with three tabs: Details, Authorization, and Access.
Step 2: Fill in the Details tab
- Name – use something descriptive, like LAN and VPN only or Admin tools, so you can pick the right list later.
- Satisfy Any – controls how the password and IP rules combine. With it off, a visitor must pass both the IP rules and the password prompt. With it on, passing either one is enough. A common setup is to turn it on so devices on your LAN get straight in, while anyone outside can still sign in with a password.
- Pass Auth to Host – when on, the visitor’s basic-auth credentials are forwarded to the app behind the proxy. Leave it off unless the app itself expects those same credentials, because some apps show errors or their own login problems when they receive an unexpected Authorization header.
Step 3: Add users on the Authorization tab (optional)
- Open the Authorization tab.
- Enter a Username and Password.
- Click to add another row if you need more than one user.
Leave this tab empty if you only want IP-based rules. Basic authentication sends credentials with every request, so only use it on hosts with an SSL certificate (HTTPS). You can request a free certificate on the host’s SSL tab.
Step 4: Add allow and deny rules on the Access tab
- Open the Access tab.
- For each rule, choose allow or deny and type an IP address or CIDR range.
- Add your allowed networks first, then finish with deny and all so everything else is blocked.
- Click Save.

Nginx checks the rules from top to bottom and uses the first one that matches, so order matters. A deny all placed above your allow rules would block everyone. Depending on your version, Nginx Proxy Manager may add a final deny rule for you when you’ve entered allow rules, but adding it yourself makes your intent clear.
CIDR examples
| Rule | What it matches |
|---|---|
| allow 192.168.1.50 | One device |
| allow 192.168.1.0/24 | 192.168.1.0 to 192.168.1.255 (a typical home LAN) |
| allow 10.0.0.0/8 | All 10.x.x.x private addresses |
| allow 172.16.0.0/12 | 172.16.0.0 to 172.31.255.255 (common Docker ranges) |
| allow 10.8.0.0/24 | A VPN subnet, such as one used by WireGuard or OpenVPN |
| deny all | Everything not matched above |
Step 5: Apply the list to a proxy host
- Go to Hosts > Proxy Hosts.
- Click the three-dot menu next to the host and choose Edit (or click Add Proxy Host for a new one).
- On the Details tab, open the Access List dropdown. It defaults to Publicly Accessible.
- Select your list and click Save.
You can attach the same list to as many hosts as you like, and editing the list later updates every host that uses it.
Step 6: Test it
- From an allowed device, open the site. It should load (or show the password prompt if Satisfy Any is off and you added users).
- From a device outside the allowed range, such as a phone on mobile data with Wi-Fi turned off, open the site. You should get a 403 Forbidden error, or a sign-in prompt if you added users and turned on Satisfy Any.
- Use a private or incognito window when testing passwords, because browsers cache basic-auth credentials until they’re closed.
Common setups
LAN only
Access tab: allow 192.168.1.0/24, then deny all. No users. Good for dashboards you only use at home.
LAN free, internet with password
Turn on Satisfy Any, add a user on the Authorization tab, and on the Access tab add allow 192.168.1.0/24 then deny all. Home devices get in without a prompt; everyone else must sign in.
Password for everyone
Add users on the Authorization tab and add a single allow all rule on the Access tab (with Satisfy Any off), so the IP check always passes and the password is always required.
New to the tool? Start with the default login and first setup.
Troubleshooting
Everyone gets 403 Forbidden, even on my LAN
- Check that deny all is the last rule, not the first.
- Confirm the IP range. Your LAN might be 192.168.0.x rather than 192.168.1.x.
- If you reach the site by its public domain from inside your network, the request may arrive from your router’s public IP (because of NAT loopback) rather than your local IP. Use local DNS so the domain resolves to the proxy’s LAN address, or allow your public IP.
- If Nginx Proxy Manager runs in Docker with a bridge network, some setups see the Docker gateway (for example, 172.17.0.1) instead of the real client IP. Check the host’s access log to see which address arrives.
The access list lets everyone in
- Make sure you selected the list on the proxy host and clicked Save.
- Check whether an allow all rule sits above your deny rules, or whether Satisfy Any is on with a rule that matches everyone.
- If traffic comes through another proxy or tunnel (such as a CDN), Nginx may see that service’s IPs instead of visitors’ IPs. IP rules won’t work as expected unless the real client IP is restored, so rely on the password prompt or your tunnel provider’s own access controls instead.
The password prompt keeps coming back
- Re-enter the password on the Authorization tab and save. Some versions don’t show the stored password, and saving with an empty field can clear it.
- Turn off Pass Auth to Host if the app behind the proxy also uses its own login.
The app breaks after adding a list
Apps with mobile clients or APIs, like media servers, often can’t handle a basic-auth prompt. Use IP rules only for those, or put them behind a VPN instead.
Frequently asked questions
Can I protect the Nginx Proxy Manager admin page with an access list?
Not directly on port 81. A common approach is to create a proxy host for the admin UI (pointing to port 81), attach an access list to it, and avoid exposing port 81 to the internet.
Does an access list replace a VPN?
No. It limits who can reach a site, but the site is still exposed to the internet. For sensitive tools, a VPN plus an access list that allows only the VPN subnet is stronger.
Can I use IPv6 addresses?
Yes. Nginx accepts IPv6 addresses and ranges, such as fd00::/8, in allow and deny rules.
Do access lists work with streams?
No. Access lists apply to proxy hosts (HTTP and HTTPS). Streams forward raw TCP or UDP traffic and don’t use them.
How do I remove an access list from a site?
Edit the proxy host, set Access List back to Publicly Accessible, and save. You can then delete the list from the Access Lists page if nothing else uses it.

Kermit Matthews is a freelance writer based in Philadelphia, Pennsylvania with more than a decade of experience writing technology guides. He has a Bachelor’s and Master’s degree in Computer Science and has spent much of his professional career in IT management.
He specializes in writing content about iPhones, Android devices, Microsoft Office, and many other popular applications and devices.